MALICIOUS — 062b6e81098f6a5dab8ff8acc194e9b0e1910a87eac3db8de46eca6e4eb142c3
MALICIOUS — 062b6e81098f6a5dab8ff8acc194e9b0e1910a87eac3db8de46eca6e4eb142c3 is a pdf sample analyzed by MalwareAnalyzer by Cyble with a malicious verdict (98/100). 4 of 54 detection engines flagged it, exhibiting 1 ATT&CK technique.
Identification
- SHA-256:
062b6e81098f6a5dab8ff8acc194e9b0e1910a87eac3db8de46eca6e4eb142c3 - SHA-1:
a305acacf05abf6cd8868847f18f95d9e42ab0c3 - MD5:
f5fb482af5b41a349f9dc8c3f5e347bb - ssdeep:
1536:w0TMuVkFHux9mQvgqGkoHFO2A0FtNb87cB1K/VWg5WOpOwrKWgaXiNUyT4:4uVgb8GkoHHntBeIg2wr20iNUD - TLSH:
T17738D1F36097ED4D738ECF03A8EB0068648BD28852A5EA50518DF67CC56C9BDFE50162 - Submitted as: 062b6e81098f6a5dab8ff8acc194e9b0e1910a87eac3db8de46eca6e4eb142c3
- File type: pdf · Size: 82061 bytes
- Verdict: malicious (98/100)
Detections (4 of 54 engines)
- MalwareAnalyser heuristics (entropy/packer): high-entropy-blob
- ClamAV (daily): Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0
- Emsisoft (Emergency Kit): PDF.Spam.Heur.1
- Kaspersky (KVRT): HEUR:Hoax.PDF.Phish.gen
MITRE ATT&CK
Why this verdict
The malicious score of 98/100 is the fusion of 9 weighted signals:
- ClamAV (daily) flagged Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0 (rule
Pdf.Phishing.Trojan-d2568dad23a94d95-d2568dad23a94d95-10044375-0) - engine signal, weight 0.90, confidence 0.95 - Emsisoft (Emergency Kit) flagged PDF.Spam.Heur.1 (rule
PDF.Spam.Heur.1) - engine signal, weight 0.55, confidence 0.85 - Kaspersky (KVRT) flagged HEUR:Hoax.PDF.Phish.gen (rule
HEUR:Hoax.PDF.Phish.gen) - engine signal, weight 0.55, confidence 0.85 - MalwareAnalyser heuristics (entropy/packer) flagged high-entropy-blob (rule
high-entropy-blob) - engine signal, weight 0.35, confidence 0.70 - Embedded network infrastructure: https://el-tall.pl/pics/file/gevux.pdf, https://crownprolaw.com/userfiles/Proj_Name/files/lufolojefojixidifoxenog.pdf, https://infravoip.com/wp-content/plugins/super-forms/uploads/php/files/d1590be5869fb97bd6f4ff5414c4a47d/9387368255.pdf - static signal, weight 0.35, confidence 0.60
- Document active content: uri-action - static signal, weight 0.30, confidence 0.60
- Packing/obfuscation: high-entropy-blob - static signal, weight 0.25, confidence 0.55
- Contacted 8 external host(s) at runtime - network signal, weight 0.12, confidence 0.55
- Extracted generic config (19 C2) (generic/advisory) - engine signal, weight 0.15, confidence 0.30
Dynamic analysis (windows)
1051 behavior events · 0 ATT&CK techniques · 1 dropped files.
Runtime network
- www.msftconnecttest.com
- rb.symcd.com
- rb.symcb.com
- inference.location.live.net
- desktop-hsgcbep._dosvc._tcp.local
- desktop-hsgcbep(1)._dosvc._tcp.local
- desktop-hsgcbep(2)._dosvc._tcp.local
- desktop-hsgcbep(3)._dosvc._tcp.local
- desktop-hsgcbep(4)._dosvc._tcp.local
- desktop-hsgcbep(5)._dosvc._tcp.local
- _dosvc._tcp.local
- ntp.ubuntu.com
- http://www.msftconnecttest.com/connecttest.txt
- http://rb.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTDRSYViRCZTxmZjLENmnwVjLly9QQU1MAGIknrOUvdk%2BJcobhHdglyA1gCEF0QyxjrOnkAh4OrdHf50xk%3D
- http://rb.symcb.com/rb.crl
- 23.40.52.209
- 23.11.37.157
- 20.190.167.20
- 52.123.252.198 AU · Sydney · AS8075 Microsoft Corporation
- 23.33.238.178
Dropped files
- root_.cache_dconf_user -
96a296d224f285c67bee93c30f8a309157f0daa35dc5b87e410b78630a09cfc7
Embedded URLs
- https://feedproxy.google.com/~r/Uplcv/~3/6naE_Nh8_CY/uplcv?utm_term=kodi+cast+to+tv
- https://el-tall.pl/pics/file/gevux.pdf
- https://crownprolaw.com/userfiles/Proj_Name/files/lufolojefojixidifoxenog.pdf
- https://infravoip.com/wp-content/plugins/super-forms/uploads/php/files/d1590be5869fb97bd6f4ff5414c4a47d/9387368255.pdf
- http://tpfish.com.taipei/archive/upload/files/76612487739.pdf
- https://studiogreenwich.ru/wp-content/plugins/super-forms/uploads/php/files/38ef1a3484f9b5bfc945dd6a5c1f62d6/10677100585.pdf
- http://vetcasatenovo.it/userfiles/files/xavelaregajenalapikax.pdf
- https://www.frontierexim.com/wp-content/plugins/super-forms/uploads/php/files/6sh4p3cs61tce2uicri85roloc/49049051519.pdf
- http://mspchicagolaw.com/customer/3/d/9/3d947ad6ce2568d98b832ccf5548371bFile/jefigolafo.pdf
- https://www.ciabrini-immobilier.com/wp-content/plugins/super-forms/uploads/php/files/liv6jfo02u6qse11p2tkf94f4p/fenedizejebilito.pdf
- https://mahanakhon.pacedev.com/ckupload/files/wibawudisipadulaxu.pdf
- https://kvgrup.com.ua/wp-content/plugins/formcraft/file-upload/server/content/files/1613d872eaa844---90573667816.pdf
- https://refundsrefunds.com/wp-content/plugins/formcraft/file-upload/server/content/files/1613d6113f0bc4---potinebubab.pdf
- https://alajuusa.ee/media/contents/file/jupogobosutumemisagazozot.pdf
- https://mysmartedu.com/uploadimages/files/mufesaregabujopuja.pdf
- https://optimuselearningschool.aels.edu/learning/site/images/uploadfiles/gipivupupunaxafevomase.pdf
- https://underworldgear.com/upload/users/files/39874278033.pdf
- https://stthomasorthodoxchurchsouthpampady.com/userfiles/file/1169747583.pdf
- http://matsonconstruction.net/userfiles/file/8950633953.pdf
- http://cbcom.fr/ressource/site-image/files/36387594931.pdf
- http://zanethompson.com/userfiles/file/32666909512.pdf
- https://indiachristian.org/uploads/files/24794552551.pdf
- http://tokyoracing.hu/userfiles/file/61852946045.pdf
- https://siphouse96.com/wp-content/plugins/super-forms/uploads/php/files/358a668fb4613355a8dbc63001bc3fd5/sewojetejalibatevamoni.pdf
- http://www.w3.org/1999/02/22-rdf-syntax-ns#
Embedded domains
- feedproxy.google.com
- el-tall.pl
- crownprolaw.com
- infravoip.com
- studiogreenwich.ru
- vetcasatenovo.it
- www.frontierexim.com
- mspchicagolaw.com
- www.ciabrini-immobilier.com
- mahanakhon.pacedev.com
- kvgrup.com.ua
- refundsrefunds.com
- mysmartedu.com
- optimuselearningschool.aels.edu
- underworldgear.com
- stthomasorthodoxchurchsouthpampady.com
- matsonconstruction.net
- cbcom.fr
- zanethompson.com
- indiachristian.org
- siphouse96.com
- www.w3.org
- purl.org
- ns.adobe.com
- tpfish.com.taipei
Embedded IP addresses
- 135.232.92.34
- 72.154.7.106
- 72.154.7.99
- 72.145.35.96
- 52.123.252.198
- 52.110.12.11
- 4.230.171.124
- 20.42.72.131
Latest analyzed threats · ATT&CK coverage
Analyzed on MalwareAnalyzer by Cyble · Open interactive report